MEDIUM
Yot CMS Cookie global.php login sql injection
Published Sep 14, 2026
6.9
MEDIUMCVSS 4.0
EPSS 0.41%
Description
A weakness has been identified in Yot CMS up to 3.3.1. Affected by this vulnerability is the function Login of the file global.php of the component Cookie Handler. This manipulation of the argument yot3_user/yot3_pass causes sql injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks.
Affected products
-
- Version 3.3.0StatusaffectedConstraints-
- Version 3.3.1StatusaffectedConstraints-
- Version
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (5)
- https://github.com/dddwmr/CVE/blob/main/YOT%20III%20cookie%20auto-login%20SQL%20injection%20enables%20forged%20administrator%20sessions%20.md exploit
- https://vuldb.com/cve/CVE-2026-90708 third-party-advisory
- https://vuldb.com/submit/918272 third-party-advisory
- https://vuldb.com/vuln/403250 vdb-entrytechnical-description
- https://vuldb.com/vuln/403250/cti signaturepermissions-required
| Link | Providers | Tags |
|---|---|---|
| https://github.com/dddwmr/CVE/blob/main/YOT%20III%20cookie%20auto-login%20SQL%20injection%20enables%20forged%20administrator%20sessions%20.md | exploit | |
| https://vuldb.com/cve/CVE-2026-90708 | third-party-advisory | |
| https://vuldb.com/submit/918272 | third-party-advisory | |
| https://vuldb.com/vuln/403250 | vdb-entrytechnical-description | |
| https://vuldb.com/vuln/403250/cti | signaturepermissions-required |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulDB
Published Sep 14, 2026
Updated Sep 15, 2026
Reserved Sep 13, 2026
Link CVE-2026-90708
CISA Vulnrichment
Updated Sep 15, 2026